Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9f2h-7v79-mxw3

Опубликовано: 14 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

Parse Javascript SDK vulnerable to prototype pollution in Parse.Object and internal APIs

Summary

Prototype pollution capabilities on various APIs.

Details

Injection of malicious payload allows attacker to remotely execute arbitrary code. Parse.Object and internal APIs are affected, specifically:

  • ParseObject.fromJSON
  • ParseObject.pin
  • ParseObject.registerSubclass
  • ObjectStateMutations (internal)
  • encode/decode (internal)

PoC

Demonstrative tests added as part of the fix.

References

Пакеты

Наименование

parse

npm
Затронутые версииВерсия исправления

< 7.0.0

7.0.0

EPSS

Процентиль: 28%
0.00101
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 6.4
nvd
4 месяца назад

Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, injection of malicious payload allows attacker to remotely execute arbitrary code. ParseObject.fromJSON, ParseObject.pin, ParseObject.registerSubclass, ObjectStateMutations (internal), and encode/decode (internal) are affected. This vulnerability is fixed in 7.0.0.

EPSS

Процентиль: 28%
0.00101
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-1321